{"id":"UBUNTU-CVE-2021-32677","details":"FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lower than 0.65.2 that used cookies for authentication in path operations that received JSON payloads sent by browsers were vulnerable to a Cross-Site Request Forgery (CSRF) attack. In versions lower than 0.65.2, FastAPI would try to read the request payload as JSON even if the content-type header sent was not set to application/json or a compatible JSON media type (e.g. application/geo+json). A request with a content type of text/plain containing JSON data would be accepted and the JSON data would be extracted. Requests with content type text/plain are exempt from CORS preflights, for being considered Simple requests. The browser will execute them right away including cookies, and the text content could be a JSON string that would be parsed and accepted by the FastAPI application. This is fixed in FastAPI 0.65.2. The request data is now parsed as JSON only if the content-type header is application/json or another JSON compatible media type like application/geo+json. It's best to upgrade to the latest FastAPI, but if updating is not possible then a middleware or a dependency that checks the content-type header and aborts the request if it is not application/json or another JSON compatible content type can act as a mitigating workaround.","modified":"2025-09-08T16:47:10Z","published":"2021-06-09T18:15:00Z","upstream":["CVE-2021-32677"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-32677"},{"type":"REPORT","url":"https://github.com/tiangolo/fastapi/security/advisories/GHSA-8h2j-cgx8-6xv7"},{"type":"REPORT","url":"https://github.com/tiangolo/fastapi/commit/fa7e3c996edf2d5482fff8f9d890ac2390dede4d"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-32677"}],"affected":[{"package":{"name":"fastapi","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/fastapi@0.63.0-2ubuntu0.1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.63.0-2","0.63.0-2ubuntu0.1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-fastapi","binary_version":"0.63.0-2ubuntu0.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-32677.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}